Daily briefing · July 5, 2026
cve-search Critical Flaw Leads July 5 Roundup Alongside Multiple PoC-Exposed Vulnerabilities
July 5, 2026 brought 84 new vulnerabilities, with one critical disclosure standing out: an unauthenticated input validation flaw in cve-search that could expose administrative credentials directly from MongoDB. The day saw no active KEV exploitation, but six of the ten highlighted CVEs carry public proof-of-concept code, significantly narrowing the window between disclosure and real-world abuse. Several entries target Turkish public-sector software from TUBITAK BILGEM, broadening the geographic scope of concern.
Today’s brief
- CRITICAL: CVE-2026-59509 in cve-search allows unauthenticated attackers to read MongoDB collections, including admin password hashes — patch or isolate immediately.
- Six of ten highlighted CVEs have public PoC exploits, meaning weaponization is already within reach of low-skilled attackers.
- Multiple TUBITAK BILGEM products (Pardus suite, Domain Joiner) are affected by privilege escalation, DNS spoofing, and credential exposure flaws.
- Network devices and web applications (UTT HiPER router, Ruijie RG-UAC, WeChat bot) round out a diverse and practically exploitable set of targets.
1
critical
0
Actively exploited
0
Before CISA
0
Weaponized
Critical highlights
1
An unauthenticated attacker can manipulate POST parameters on the /fetch_cve_data endpoint to query arbitrary MongoDB collections in cve-search, including the mgmt_users collection containing admin usernames and password hashes. With a public PoC already available, any exposed instance should be treated as compromised until patched or isolated.
2
Incorrect permission assignment in Pardus-Parental-Control (versions up to 0.5.1) allows attackers to perform DNS spoofing, potentially redirecting users to malicious infrastructure. Organizations running this parental control solution on Turkish Pardus Linux deployments should upgrade to 0.7.0 or later without delay.
3
A stack-based buffer overflow in the UTT HiPER 1250GW router's web endpoint (via the ssid argument) can be triggered remotely, and a public exploit has already been disclosed. Routers exposed to the internet or untrusted networks are at direct risk of remote code execution.
4
Pardus Domain Joiner (before 0.5.4) exposes sensitive credentials through process invocation in a way visible to local observers, enabling credential excavation by low-privileged users. Systems joined to domains using this tool should be updated and credentials rotated as a precaution.
5
A missing authorization check in Pardus Update (before 0.6.6) can be leveraged for local privilege escalation, allowing an attacker with limited access to gain elevated system rights. This is especially concerning in multi-user or shared environments running the Pardus Linux distribution.
6
A path traversal vulnerability in AIL Framework's PDF object handling allows authenticated users to read files outside the intended PDF storage directory. Defenders should apply the fix from commit 14c618fce4d1df02358717c48ea903706abecdf2 and audit file access logs for anomalous path patterns.
7
Missing authentication on the wx endpoint's verify_server function in chatgpt-on-wechat CowAgent 2.1.0 allows remote attackers to interact with the WeChat integration without credentials, with a public PoC already available. Instances exposed to the internet should be upgraded or placed behind authentication controls immediately.
8
An unrestricted file upload vulnerability in Ruijie RG-UAC's user_auth_commit.php allows remote attackers to upload arbitrary files, a classic vector for webshell deployment and full system compromise. The public exploit makes this an urgent patching priority for any organization using this unified access controller.
9
SQL injection via the street, city, and status parameters in the Smart Parking System 1.0 (/parkings/parkings.php) can be exploited remotely to extract or manipulate the underlying database. A public exploit is available, making any publicly accessible deployment an easy target for data theft.
10
A SQL injection flaw in SourceCodester Class and Exam Timetabling System 1.0 (/edit_product.php) via the ID parameter allows remote attackers to interact with the backend database. With a published exploit, educational institutions running this system should restrict access and apply available patches immediately.
Today’s recommendation: Prioritize patching or network-isolating CVE-2026-59509 in any cve-search deployment, as unauthenticated credential theft poses an immediate takeover risk; simultaneously audit all PoC-exposed entries (especially CVE-2026-14721, CVE-2026-14736, and CVE-2026-14735) and apply vendor updates or compensating controls before attackers operationalize the available exploits.
With six public exploits disclosed in a single day spanning routers, web apps, and platform tools, now is the right moment to validate which of these affected components actually exist in your environment and confirm your detection coverage can catch exploitation attempts.Find out in minutes, with a free exposure assessment, where your organization is truly exposed.Meet the Autonomous AI Pentest Agent →Previous briefings
September 20, 2026 — Dozens of Critical PoC Flaws Surface in Routers and Research Tools, But No Active Exploitation DetectedSeptember 19, 2026 — Calm Vulnerability Day Masks Serious Flaws in Routers, WordPress, and SuricataSeptember 18, 2026 — WordPress, IBM, and vm2 Flaws Anchor a High-Alert Day With 5 CVEs Already Under Active ExploitationSeptember 17, 2026 — Six CVSS 10.0 Azure Flaws Lead a Heavy Patch Day as Acronis Backup Plugin Faces Active ExploitationSeptember 16, 2026 — Cisco Infrastructure Flooded With CVSS 10 Flaws as VulnCheck Spots Active Exploitation Before CISASeptember 15, 2026 — Oracle Patch Tuesday Surge and Yonyou Active Exploitation Drive ATTENTION-Level AlertSeptember 14, 2026 — Cisco Secure Email Under Active Exploitation as 58 Critical CVEs SurfaceSeptember 13, 2026 — WordPress Plugin Flaw Leads Quiet Day With 8 Critical CVEs and No Active ExploitationSeptember 12, 2026 — WordPress Plugin Blitz: Nine Critical RCE and Takeover Flaws Disclosed on a Quiet Exploit DaySeptember 11, 2026 — GitLab Critical Zero-Day Under Active Exploitation Leads a Heavy Patch Day with 36 Critical CVEsSeptember 10, 2026 — Ten Critical CVEs Published on a Calm Threat Day as Brazil Faces Ransomware SurgeSeptember 9, 2026 — Three CVEs Already Exploited Before CISA Confirmation, Dual Check Point RCE and cPanel SQLi-to-Root Round Out a High-Alert DaySeptember 8, 2026 — Windows Under Active Exploit, ScreenConnect Zero-Day Detected Before CISA: September 8 Security BulletinSeptember 7, 2026 — 22 Critical CVEs Published on a Quiet Day, With Heavy Ransomware Pressure on Brazilview full archive →